7,068 questions with Windows for business | Windows Client for IT Pros | Directory services | Active Directory tags
Need help recovering an orphaned AD child domain before Tech Refresh – missing Forest-level FSMO roles and Enterprise Admins
Hi Microsoft Community, I need advice on an Active Directory environment that appears to have been left in an incomplete state after the original parent/forest-root domain was decommissioned. Current environment For example, the original AD structure…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
August 2026 CU breaks/fixes secure channel trust with Credential Manager enabled
It seems that a constant fail/repair occurs in netlogon.log where Windows 11 patched servers on August 2026 have issues and report NETLOGON 5419 errors in the system event log. This does not happen if CM is disabled. example: 08/24 10:40:54 [SESSION]…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
How to switch from Private to Domain network - Windows server 2019 RODC
I have created a windows server 2019 RODC, it is working fine. But, it automatically goes to "Private Network". I have other windows server 2012 R2 RODC, they are in "Domain Network". I read some article to restart "Network…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
How to get a hold of Microsoft technicians to help with Domain Controller issue?
We have some questions about some logs that we are seeing on our domain controllers and Microsoft has made it impossible to get a hold of a live technician. The Engage Center says that we cannot purchase services for the issues that we are experiencing…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Forest trust SID filtering vs SID history — are these the same setting or two different things?
Hello, Working through an AD security finding in an isolated lab and want a sanity check on my understanding before I take this to a client. The finding: "Domain trust to a third-party domain without quarantine" (ANSSI…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
msExchHideFromAddressLists isn't in AD and I can't add it but need to remove people from GAL
We have some users who are no longer with the organization, but we can't remove them from EAC - getting "Couldn't update mailbox global address list info". Please help.
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
How to enforce Edge Browser to stop using Personal and only allows Work account to sync?
Would it be possible to enforce and only allow the Microsoft Edge browser to log in and open as a Work Account instead of as a Personal account? My corporate workstation has been configured as Hybrid Azure AD Joined and managed by Intune, so I wonder if…
Microsoft Security | Intune | Configuration
Setting up and managing device configurations using Intune
Microsoft Security | Intune | Grouping
Organizing devices and users into groups for policy application
Microsoft Security | Intune | Other
Other Intune-related topics, including unsupported scenarios and platform-specific behaviors
Microsoft Edge | Microsoft Edge development
Developing and testing features or extensions for Microsoft Edge
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
access ro remote computer via computer management
In microsoft domain what requirements to connect remote computer via computer management ? My client is Window 11 and I use AD account which belongs to local administrators group of remote computer (Windows 10) When I open computer management to explore…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft NTLM Retirement.
Microsoft is retiring NTLM (New Technology LAN Manager), a legacy authentication protocol that has been part of Windows environments for more than 30 years. By when Microsoft is going to stop or deprecate completely, is there any deadline for…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Understanding Kerberos Encryption Type Selection When msDS-SupportedEncryptionTypes = 28 (RC4 + AES128 + AES256)
Hello Experts, I am trying to understand how Active Directory and Kerberos choose the encryption type when a service account supports multiple encryption types. For example, the msDS-SupportedEncryptionTypes attribute can have the following values: RC4…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
windows password for microsoft edge password will not accept my password
Microsoft Edge is trying to show passwords. Enter your windows password to allow this. None of my passwords are accepted and I cannot access any of my stored passwords. Is there a forgot password or a simple fix so I can access my passwords stored on…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Remediating stale adminCount=1 accounts: What should be verified before clearing adminCount and enabling inheritance?
Hello, I'm working on a PowerShell script to remediate stale protected accounts in Active Directory. The script identifies user accounts that have adminCount=1 but are no longer members (including nested membership) of any protected administrative…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Forest trust or external trust? Only NTLM working, Kerberos failing
Forest trust or external trust? Only NTLM working, Kerberos failing
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
I am in the process of migrating my domain controllers to new IPs and since we have several applications that use LDAP for authentication, I must change the DC ip in the settings of those applications (JIRA , vmware , ...). my question is: is there a sol
I am in the process of migrating my domain controllers to new IPs and since we have several applications that use LDAP for authentication, I must change the DC ip in the settings of those applications (JIRA , vmware , ...). my question is: is there a…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows 2019 gpresult /h AD / SYSVOL Version Mismatch
Hello. I'm trying to understand how to solve this issue: some GPO are not applied to some server due to a AD / SYSVOL Version Mismatch. I'm looking for a solution for Windows 2019. The only solution I found is about Windows 8.1 or Windows…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
Numerous lockouts on some users
I have had some issues with 4 users getting locked out during the day. The only thing that seems ot be in all the event logs is DSATS. This is a remote desktop that is outside a network users can log into to do their work if needed. It's outside the…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Does GPO "Delete User Profiles Older Than X Days" Remove Local Administrator Profile?
Hello, I am using the Group Policy setting "Automatically delete user profiles older than a specified number of days on system restart" to clean up old user profiles on our Windows systems. I would like to confirm: Does this policy delete the…
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
How do I fix a DC that hasn't replicated in 55 days
Hi, I have wasted weeks in trying and have exhausted the brains trust that is the internet in trying to find a way to get one of our DCs to replicate again, to no joy, and I have come to the realization that the domain controller has been disconnected…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Event 1126 error - on additional DC after setting up not taking over - not advertising as a globla catalog
Last year, I deployed a new Windows Server 2022 Domain Controller in our environment as an additional DC. The goal was to upgrade our Active Directory environment from Windows Server 2016 (which has reached end of support) to Windows Server 2022. During…
Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Admin prompt when trying to change IP settings under network configuration.
After upgrading from Win10 to Win11, our techs that are placed in the Network Configuration Operators group via GPO can no longer change their IP settings without getting an Administrator credentials prompt. Since they are not Administrators they can no…